dependency-upgrade

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references a changelog from Facebook's official React repository on GitHub. This is a standard practice for assessing breaking changes and originates from a trusted organization.- [COMMAND_EXECUTION]: The instructions utilize established package management commands (npm, yarn) and well-known utility tools (npm-check-updates, madge, changelog-parser) for dependency auditing and visualization.- [DATA_EXFILTRATION]: No patterns for accessing sensitive system files or transmitting data to unauthorized external endpoints were detected. Network activity is limited to standard package audits and fetching documentation from trusted sources.- [PROMPT_INJECTION]: The skill's instructions are focused on development workflows and do not contain patterns designed to override agent safety protocols or hijack behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 11:58 PM
Security Audit — agent-trust-hub — dependency-upgrade